CVE Database /
CVE-2025-12800
CVE · Medium
CVE-2025-12800 — Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12800
|
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.6 |
Server-Side Request Forgery (SSRF) |
Medium
6.4
|
< 7.4.6
|
7.4.6 |
2025-11-23 |
—
|
CVE-2025-12800
The Shortcodes Ultimate plugin for WordPress contains a vulnerability that allows attackers with Administrator-level access and above to make unauthorized web requests to arbitrary locations, potentially allowing them to access or modify sensitive information from internal services. This vulnerability can be exploited even by lower-level attackers if the 'Unsafe features' option is enabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings